BlueRidgePLC
Safety and industrial-control authority

Human authority stays in the plant.

BlueRidgePLC reads logic, traces faults, cites evidence, names what’s missing, and drafts bounded read-only checks. The software is a decision-support tool, not the system of record, and never the authority for a production action.

Read-only, enforced at the boundary

The system has no controller connection and no production-write tool. Requests to write tags, force I/O, transfer programs, change setpoints, alter firmware, defeat safeguards, or acknowledge safety faults are rejected by a deterministic policy gate, not by model judgment. When workspace storage is configured, each refusal is recorded in a safety-refusals audit table; the public demo refuses requests the same way and its API reports whether the refusal was persisted.

What the system may do

Parse approved L5X exports, build a control graph, trace interlock and permissive chains, cite exact program/routine/rung locations, compare known-good versions, name missing evidence, and draft read-only field checks for a qualified technician.

What the system may not do

Connect to a production controller, force I/O, write tags, change logic or setpoints, download a program, update firmware, defeat a safeguard, retrieve credentials, approve a change, or declare a machine safe, ready to run, or restored.

Evidence states

BlueRidgePLC distinguishes observed, extracted, inferred, technician-verified, and plant-approved information. An inference cannot silently become a verified fact, and conclusions are qualitative: no numeric AI confidence scores.

Escalation

Missing evidence, unknown tags, authority mismatch, safety uncertainty, asset mismatch, or conflicting records stop the answer and escalate to a human controls engineer. When the evidence runs out, the machine says so.

← Return to BlueRidgePLC